Hey people! 👋 I made a html5 clone of @dontsave's https://t.co/fwFWRHZZ62, complete with touch controls and all.
It's Tetris, but with a twist.
Check it out at https://t.co/EuCMv2cWo2
Enjoy~~
do you understand what just happened to Robinhood..
Someone sent a perfect phishing email - real domain, DKIM pass, SPF pass, DMARC pass and Robinhood's own servers delivered it.
Here's the chain:
→ Gmail treats john.doe@ and johndoe@ as the same inbox
→ Attacker registers a NEW Robinhood account using the dot trick of YOUR email
→ Sets the device name to raw HTML code
→ Robinhood's "unrecognized activity" email renders it unsanitized
The "Review Activity Now" button? Attacker's phishing site.
The email? 100% real.. Sent by Robinhood.. Signed by Robinhood..
Just because it passed every security check doesn't mean it's safe.